Description
The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to read portions of memory via a username without a trailing null byte, which causes a buffer over-read.
Published: 2006-05-05
Score: 5.0 Medium
EPSS: 82.3% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-1071-1 New MySQL 3.23 packages fix several vulnerabilities
Debian DSA Debian DSA DSA-1073-1 New MySQL 4.1 packages fix several vulnerabilities
Debian DSA Debian DSA DSA-1079-1 New MySQL 4.0 packages fix several vulnerabilities
Ubuntu USN Ubuntu USN USN-283-1 MySQL vulnerabilities
References
Link Providers
http://bugs.debian.org/365938 cve-icon cve-icon
http://dev.mysql.com/doc/refman/5.0/en/news-5-0-21.html cve-icon cve-icon
http://docs.info.apple.com/article.html?artnum=305214 cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html cve-icon cve-icon
http://lists.suse.com/archive/suse-security-announce/2006-Jun/0011.html cve-icon cve-icon
http://secunia.com/advisories/19929 cve-icon cve-icon
http://secunia.com/advisories/20002 cve-icon cve-icon
http://secunia.com/advisories/20073 cve-icon cve-icon
http://secunia.com/advisories/20076 cve-icon cve-icon
http://secunia.com/advisories/20223 cve-icon cve-icon
http://secunia.com/advisories/20241 cve-icon cve-icon
http://secunia.com/advisories/20253 cve-icon cve-icon
http://secunia.com/advisories/20333 cve-icon cve-icon
http://secunia.com/advisories/20424 cve-icon cve-icon
http://secunia.com/advisories/20457 cve-icon cve-icon
http://secunia.com/advisories/20625 cve-icon cve-icon
http://secunia.com/advisories/20762 cve-icon cve-icon
http://secunia.com/advisories/24479 cve-icon cve-icon
http://secunia.com/advisories/29847 cve-icon cve-icon
http://securityreason.com/securityalert/840 cve-icon cve-icon
http://securitytracker.com/id?1016017 cve-icon cve-icon
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.599377 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-236703-1 cve-icon cve-icon
http://www.debian.org/security/2006/dsa-1071 cve-icon cve-icon
http://www.debian.org/security/2006/dsa-1073 cve-icon cve-icon
http://www.debian.org/security/2006/dsa-1079 cve-icon cve-icon
http://www.gentoo.org/security/en/glsa/glsa-200605-13.xml cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2006:084 cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2006-06-02.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2006-0544.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/432733/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/434164/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/17780 cve-icon cve-icon
http://www.trustix.org/errata/2006/0028 cve-icon cve-icon
http://www.us-cert.gov/cas/techalerts/TA07-072A.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/1633 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/0930 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/1326/references cve-icon cve-icon
http://www.wisec.it/vulns.php?page=7 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/26236 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2006-1516 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9918 cve-icon cve-icon
https://usn.ubuntu.com/283-1/ cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2006-1516 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: debian

Published:

Updated: 2024-08-07T17:12:22.153Z

Reserved: 2006-03-30T00:00:00.000Z

Link: CVE-2006-1516

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2006-05-05T12:46:00.000

Modified: 2026-04-16T00:27:16.627

Link: CVE-2006-1516

cve-icon Redhat

Severity : Moderate

Publid Date: 2006-05-02T00:00:00Z

Links: CVE-2006-1516 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses